← Legal Landscape

Coming up01/10/2026 · Section 51 NISG 2026

NISG 2026 takes effect (Austria)

What applies

On 1 October 2026 — a date we derive, not one printed in the statute: Section 51 NISG 2026 sets entry into force at nine months after publication, rolled to the next month's first day, and publication was on 23 December 2025 — the NISG 2026 enters into force: Austria's transposition of the NIS2 Directive. The logic mirrors Germany's BSIG, but with its own reporting channels, its own authority structure, and its own registration duties.

For companies with sites in both countries, that means two regimes, one security standard. Anyone who has already built framework-neutral measures reports twice; anyone running a separate project per country pays twice.

Who it affects

Companies established or with a branch in Austria in the NIS2 sectors — and German companies with Austrian subsidiaries or customers.

Example (fictional): The double report at three in the morning

An IT service provider with sites in Munich and Linz is hit by a ransomware attack. German headquarters reports to the BSI on time; in the middle of the night, nobody thinks of the Austrian reporting duty, and the deadline passes.

The Austrian authority finds out from the press. What was a cleanly managed incident becomes a supervisory proceeding in Linz — not because of the attack, but because of the missed report.

The risks, plainly stated

Fines under the Austrian regime

NISG 2026 tiers its fines (Section 45 NISG 2026): substantive violations — such as missing risk-management measures or a missed incident report — can cost essential entities up to €10 million or 2% of worldwide annual turnover, and important entities up to €7 million or 1.4%. A late registration alone sits in its own, much lower category (Section 45(4)(1) NISG 2026).

Two reporting clocks, half the time

In a real incident, German and Austrian clocks run in parallel — anyone who has only rehearsed one reporting channel misses the second.

Doubled project effort

Without a framework-neutral base, DE and AT sites end up building separate compliance programmes — double the cost for the same result.

Your next steps

  1. 01Check whether Austrian sites or subsidiaries fall under the NISG
  2. 02Extend your reporting process to cover the AT channel, and run through it once
  3. 03Keep measures framework-neutral — implement once, evidence twice

In Compliverse

The compass turns exactly these steps into measures in your plan automatically — with deadlines, owners, and evidence.

Plain-language product content, not legal advice · Case studies are fictional · Fine amounts as stated in the legal act (“up to”)